Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Linux RT (Live Patch 1 SLE 15 SP4)
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Linux RT (Live Patch 1 SLE 15 SP4)
ID: SUSE-SU-2023:2371-1
Distribution: SUSE
Plattformen: SUSE Linux Enterprise Micro 5.3, SUSE Linux Enterprise Real Time 15 SP4, SUSE Linux Enterprise High Performance Computing 15 SP4, SUSE Linux Enterprise Server 15 SP4, SUSE Linux Enterprise Server for SAP Applications 15 SP4, SUSE Linux Enterprise Micro 5.4, SUSE Linux Enterprise Live Patching 15-SP4
Datum: Mo, 5. Juni 2023, 20:26
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0386
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23454
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28464
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0461
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2162
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1989
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1281
Applikationen: RT-Preempt-Realtime-Patch

Originalnachricht

--===============5606811940940231977==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit



# Security update for the Linux Kernel RT (Live Patch 1 for SLE 15 SP4)

Announcement ID: SUSE-SU-2023:2371-1
Rating: important
References:

* #1207188
* #1208911
* #1209683
* #1210499
* #1210500
* #1210662
* #1211111


Cross-References:

* CVE-2023-0386
* CVE-2023-0461
* CVE-2023-1281
* CVE-2023-1989
* CVE-2023-2162
* CVE-2023-23454
* CVE-2023-28464


CVSS scores:

* CVE-2023-0386 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-0386 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-0461 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-0461 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-1281 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-1281 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-1989 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-1989 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-2162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-2162 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2023-23454 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-23454 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2023-28464 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-28464 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H


Affected Products:

* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP4



An update that solves seven vulnerabilities can now be installed.

## Description:

This update for the Linux Kernel 5.14.21-150400_15_5 fixes several issues.

The following security issues were fixed:

* CVE-2023-28464: Fixed user-after-free that could lead to privilege
escalation in hci_conn_cleanup in net/uetooth/hci_conn.c (bsc#1211111).
* CVE-2023-1989: Fixed a use after free in btsdio_remove (bsc#1210500).
* CVE-2023-0386: Fixed privileges escalation for low-privileged users in the
OverlayFS subsystem (bsc#1210499).
* CVE-2023-1281: Fixed use after free that could lead to privilege escalation
in tcindex (bsc#1209683).
* CVE-2023-2162: Fixed an use-after-free flaw in iscsi_sw_tcp_session_create
(bsc#1210662).
* CVE-2023-0461: Fixed use-after-free in icsk_ulp_data (bsc#1208911).
* CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler
(bsc#1207188).

## Patch Instructions:

To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-2371=1
SUSE-SLE-
Module-Live-Patching-15-SP4-2023-2370=1

## Package List:

* SUSE Linux Enterprise Live Patching 15-SP4 (x86_64)
* kernel-livepatch-5_14_21-150400_15_5-rt-debuginfo-6-150400.2.2
* kernel-livepatch-5_14_21-150400_15_8-rt-debuginfo-5-150400.2.2
* kernel-livepatch-SLE15-SP4-RT_Update_1-debugsource-6-150400.2.2
* kernel-livepatch-5_14_21-150400_15_5-rt-6-150400.2.2
* kernel-livepatch-5_14_21-150400_15_8-rt-5-150400.2.2
* kernel-livepatch-SLE15-SP4-RT_Update_2-debugsource-5-150400.2.2

## References:

* https://www.suse.com/security/cve/CVE-2023-0386.html
* https://www.suse.com/security/cve/CVE-2023-0461.html
* https://www.suse.com/security/cve/CVE-2023-1281.html
* https://www.suse.com/security/cve/CVE-2023-1989.html
* https://www.suse.com/security/cve/CVE-2023-2162.html
* https://www.suse.com/security/cve/CVE-2023-23454.html
* https://www.suse.com/security/cve/CVE-2023-28464.html
* https://bugzilla.suse.com/show_bug.cgi?id=1207188
* https://bugzilla.suse.com/show_bug.cgi?id=1208911
* https://bugzilla.suse.com/show_bug.cgi?id=1209683
* https://bugzilla.suse.com/show_bug.cgi?id=1210499
* https://bugzilla.suse.com/show_bug.cgi?id=1210500
* https://bugzilla.suse.com/show_bug.cgi?id=1210662
* https://bugzilla.suse.com/show_bug.cgi?id=1211111


--===============5606811940940231977==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit





<div class="container">
<h1>Security update for the Linux Kernel RT (Live Patch 1 for SLE 15
SP4)</h1>

<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2023:2371-1</td>
</tr>

<tr>
<th>Rating:</th>
<td>important</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1207188">#1207188</a>
</li>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1208911">#1208911</a>
</li>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1209683">#1209683</a>
</li>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1210499">#1210499</a>
</li>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1210500">#1210500</a>
</li>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1210662">#1210662</a>
</li>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1211111">#1211111</a>
</li>

</ul>
</td>
</tr>

<tr>
<th>
Cross-References:
</th>
<td>
<ul>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-0386.html">CVE-2023-0386</a>
</li>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-0461.html">CVE-2023-0461</a>
</li>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-1281.html">CVE-2023-1281</a>
</li>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-1989.html">CVE-2023-1989</a>
</li>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-2162.html">CVE-2023-2162</a>
</li>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-23454.html">CVE-2023-23454</a>
</li>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-28464.html">CVE-2023-28464</a>
</li>

</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-0386</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-0386</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-0461</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-0461</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-1281</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-1281</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-1989</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-1989</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">7.0</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-2162</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">7.0</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-2162</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">5.5</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-23454</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-23454</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">5.5</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-28464</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2023-28464</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">7.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
</li>

</ul>
</td>
</tr>

<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">

<li class="list-group-item">SUSE Linux
Enterprise High Performance Computing 15 SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise Live Patching 15-SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise Micro 5.3</li>

<li class="list-group-item">SUSE Linux
Enterprise Micro 5.4</li>

<li class="list-group-item">SUSE Linux
Enterprise Real Time 15 SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 15 SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise Server for SAP Applications 15 SP4</li>

</ul>
</td>
</tr>
</tbody>
</table>

<p>An update that solves seven vulnerabilities can now be
installed.</p>

<h2>Description:</h2>
<p>This update for the Linux Kernel 5.14.21-150400_15_5 fixes several
issues.</p>
<p>The following security issues were fixed:</p>
<ul>
<li>CVE-2023-28464: Fixed user-after-free that could lead to privilege
escalation in hci_conn_cleanup in net/uetooth/hci_conn.c (bsc#1211111).</li>
<li>CVE-2023-1989: Fixed a use after free in btsdio_remove
(bsc#1210500).</li>
<li>CVE-2023-0386: Fixed privileges escalation for low-privileged users
in the OverlayFS subsystem (bsc#1210499).</li>
<li>CVE-2023-1281: Fixed use after free that could lead to privilege
escalation in tcindex (bsc#1209683).</li>
<li>CVE-2023-2162: Fixed an use-after-free flaw in
iscsi_sw_tcp_session_create (bsc#1210662).</li>
<li>CVE-2023-0461: Fixed use-after-free in icsk_ulp_data
(bsc#1208911).</li>
<li>CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler
(bsc#1207188).</li>
</ul>



<h2>Patch Instructions:</h2>
<p>
To install this SUSE Important update use the SUSE recommended
installation methods like YaST online_update or "zypper
patch".<br/>

Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">

<li class="list-group-item">
SUSE Linux Enterprise Live Patching 15-SP4


<br/>
<code>zypper in -t patch
SUSE-SLE-Module-Live-Patching-15-SP4-2023-2371=1 SUSE-SLE-Module-Live-Patching-15-SP4-2023-2370=1</code>



</li>

</ul>

<h2>Package List:</h2>
<ul>


<li>
SUSE Linux Enterprise Live Patching 15-SP4 (x86_64)
<ul>


<li>kernel-livepatch-5_14_21-150400_15_5-rt-debuginfo-6-150400.2.2</li>


<li>kernel-livepatch-5_14_21-150400_15_8-rt-debuginfo-5-150400.2.2</li>


<li>kernel-livepatch-SLE15-SP4-RT_Update_1-debugsource-6-150400.2.2</li>


<li>kernel-livepatch-5_14_21-150400_15_5-rt-6-150400.2.2</li>


<li>kernel-livepatch-5_14_21-150400_15_8-rt-5-150400.2.2</li>


<li>kernel-livepatch-SLE15-SP4-RT_Update_2-debugsource-5-150400.2.2</li>

</ul>
</li>


</ul>


<h2>References:</h2>
<ul>


<li>
<a href="https://www.suse.com/security/cve/CVE-2023-0386.html">https://www.suse.com/security/cve/CVE-2023-0386.html</a>
</li>



<li>
<a href="https://www.suse.com/security/cve/CVE-2023-0461.html">https://www.suse.com/security/cve/CVE-2023-0461.html</a>
</li>



<li>
<a href="https://www.suse.com/security/cve/CVE-2023-1281.html">https://www.suse.com/security/cve/CVE-2023-1281.html</a>
</li>



<li>
<a href="https://www.suse.com/security/cve/CVE-2023-1989.html">https://www.suse.com/security/cve/CVE-2023-1989.html</a>
</li>



<li>
<a href="https://www.suse.com/security/cve/CVE-2023-2162.html">https://www.suse.com/security/cve/CVE-2023-2162.html</a>
</li>



<li>
<a href="https://www.suse.com/security/cve/CVE-2023-23454.html">https://www.suse.com/security/cve/CVE-2023-23454.html</a>
</li>



<li>
<a href="https://www.suse.com/security/cve/CVE-2023-28464.html">https://www.suse.com/security/cve/CVE-2023-28464.html</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1207188">https://bugzilla.suse.com/show_bug.cgi?id=1207188</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1208911">https://bugzilla.suse.com/show_bug.cgi?id=1208911</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1209683">https://bugzilla.suse.com/show_bug.cgi?id=1209683</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1210499">https://bugzilla.suse.com/show_bug.cgi?id=1210499</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1210500">https://bugzilla.suse.com/show_bug.cgi?id=1210500</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1210662">https://bugzilla.suse.com/show_bug.cgi?id=1210662</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1211111">https://bugzilla.suse.com/show_bug.cgi?id=1211111</a>
</li>


</ul>

</div>

--===============5606811940940231977==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung